INNER CODE UNIT · Python

_check_url

tiliondev/fortress · mcp/server.py:77

async def _check_url(url: str) -> None:
    """SSRF guard for the local MCP: refuse localhost / private / cloud-metadata
    targets unless the operator opts in with TILION_ALLOW_PRIVATE_EGRESS=1.

    DNS resolution goes through the event loop's ASYNC resolver — a blocking
    socket.getaddrinfo here would stall every concurrent tool call and could not
    be cancelled by the per-tool timeout."""
    if _env("ALLOW_PRIVATE_EGRESS", "0") == "1":
        return
    from urllib.parse import urlparse

    host = (urlparse(url).hostname or "").strip("[]")
    if not host:
        raise ValueError(f"invalid url: {url!r}")
    if host.lower() in ("localhost", "metadata.google.internal"):
        raise ValueError(f"refused private/metadata host {host!r} "
                         "(set TILION_ALLOW_PRIVATE_EGRESS=1 to allow)")
    if _ip_blocked(host):                     # host is already a literal IP

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…